Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-346",
"CWE-693"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102673.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "41.10.4"
},
{
"introduced": "42.0.0-alpha.1"
},
{
"fixed": "42.5.2"
},
{
"introduced": "43.0.0-alpha.1"
},
{
"fixed": "43.0.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102673.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"337100518295769840013293958179043012193",
"86129527286300239447279212798851890603",
"64594244635636088983275770090313221792",
"246773448299855935828646370455452546811",
"298746740956993120340707812112976354173",
"224056369280658286479665002420760541650",
"107277440710212529560696954111275723460",
"241971597370638958446471162570613630715",
"67470323471439808387813763239302192076",
"244759922769832943361626283261481905011",
"124519459957339233158380044280583949480",
"86002622541661781336503745577338161251",
"13415049600985281290722360075542761292",
"37209829834150884082258036799983735055",
"278014000792034411082817682206969939341",
"121951299309560609359872856185575282840",
"243167345859589113771150204210326472766",
"167490884979004683311950052793028272049",
"18182237239928577854429213040599289817",
"233893617823787022389818830588389982798",
"206485576675150764266599022334678971552",
"16442111000798802849436320524406849900",
"167408454601894000773509001348794090649",
"88788752803326559499283660137822035254",
"72727375855400361704763958375961258522",
"38643915436236790639124195631581856009",
"154129400451289791111987500175155241703",
"83373698591546707059601685504085807838",
"210245179682780583837820171811438206577",
"180402092053964992187545904932732660986",
"283470264007681337010003378532573045696",
"119197397100142948970674350960989689519",
"95289522883048457379486357009997317591",
"188012090332244541255089765791255447534",
"36965479763572780120031153573203232284",
"53586724714886111780899110718956287470",
"125169168603412943540892748025644328390",
"138121020606588995755592278155315353471",
"153736826164575894005482689277701806880",
"118701613432144359973145833542929745506"
],
"threshold": 0.9
},
"id": "CVE-2026-102673-10409b92",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/7ea14d5f55ecb11a30447701ddca16b3feee0bba",
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"337100518295769840013293958179043012193",
"86129527286300239447279212798851890603",
"64594244635636088983275770090313221792",
"246773448299855935828646370455452546811",
"298746740956993120340707812112976354173",
"224056369280658286479665002420760541650",
"107277440710212529560696954111275723460",
"241971597370638958446471162570613630715",
"67470323471439808387813763239302192076",
"244759922769832943361626283261481905011",
"124519459957339233158380044280583949480",
"86002622541661781336503745577338161251",
"13415049600985281290722360075542761292",
"37209829834150884082258036799983735055",
"278014000792034411082817682206969939341",
"121951299309560609359872856185575282840",
"243167345859589113771150204210326472766",
"167490884979004683311950052793028272049",
"18182237239928577854429213040599289817",
"233893617823787022389818830588389982798",
"206485576675150764266599022334678971552",
"16442111000798802849436320524406849900",
"167408454601894000773509001348794090649",
"88788752803326559499283660137822035254",
"72727375855400361704763958375961258522",
"38643915436236790639124195631581856009",
"154129400451289791111987500175155241703",
"83373698591546707059601685504085807838",
"210245179682780583837820171811438206577",
"180402092053964992187545904932732660986",
"283470264007681337010003378532573045696",
"119197397100142948970674350960989689519",
"95289522883048457379486357009997317591",
"188012090332244541255089765791255447534",
"36965479763572780120031153573203232284",
"53586724714886111780899110718956287470",
"125169168603412943540892748025644328390",
"138121020606588995755592278155315353471",
"153736826164575894005482689277701806880",
"118701613432144359973145833542929745506"
],
"threshold": 0.9
},
"id": "CVE-2026-102673-3b492893",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/e26b2640e7795c42bfb111b76009cbb4327c9a69",
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"337100518295769840013293958179043012193",
"86129527286300239447279212798851890603",
"64594244635636088983275770090313221792",
"246773448299855935828646370455452546811",
"298746740956993120340707812112976354173",
"224056369280658286479665002420760541650",
"107277440710212529560696954111275723460",
"252317018371539679980945791405035271871",
"273057481883841445605895885656124996792",
"99626613113370086301619905621727241640",
"5972389587480986637307110444702648256",
"63763540516200097404713558070784230670",
"16287636031859294043708609296893780599",
"229007350793134705639316087852111996740",
"42978286072854337637642584465149601369",
"121951299309560609359872856185575282840",
"243167345859589113771150204210326472766",
"167490884979004683311950052793028272049",
"18182237239928577854429213040599289817",
"233893617823787022389818830588389982798",
"206485576675150764266599022334678971552",
"16442111000798802849436320524406849900",
"167408454601894000773509001348794090649",
"88788752803326559499283660137822035254",
"72727375855400361704763958375961258522",
"38643915436236790639124195631581856009",
"154129400451289791111987500175155241703",
"83373698591546707059601685504085807838",
"210245179682780583837820171811438206577",
"180402092053964992187545904932732660986",
"283470264007681337010003378532573045696",
"119197397100142948970674350960989689519",
"95289522883048457379486357009997317591",
"188012090332244541255089765791255447534",
"36965479763572780120031153573203232284",
"53586724714886111780899110718956287470",
"125169168603412943540892748025644328390",
"138121020606588995755592278155315353471",
"153736826164575894005482689277701806880",
"118701613432144359973145833542929745506"
],
"threshold": 0.9
},
"id": "CVE-2026-102673-9b7df09e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/ebe1165ee2b05c203c26dd2244ef1c5b9b1c04da",
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc"
}
}
]
"2026-10-02T08:13:49Z"